← Back to home

Security

Last updated: 2026

1. Your data is isolated by default

Every flight log, equipment entry, client note, and message is stored with a row-level security policy that ties it to your signed-in account. The backend only returns rows that belong to you, so one pilot cannot access another pilot's data.

2. Encrypted connections

All traffic between the AeroNote app and our backend is sent over HTTPS using TLS encryption. Your sign-in session, logs, and exports are protected in transit.

3. Authentication

Sign-in uses email and password or OAuth through Google and Apple. Passwords must be at least 10 characters and include a number and a symbol. We never store passwords in plain text.

4. Payments are handled by Paddle

AeroNote does not store your card or billing details. Paddle.com is the Merchant of Record for all purchases and handles payment processing, tax, and billing support.

5. Verified webhooks

Subscription events from Paddle are verified with a signature before they are written to your account. This prevents tampered or fake subscription updates.

6. You control your account

You can export your logbook to PDF or CSV at any time, and you can permanently delete your account from Settings. Deletion cancels any active subscription first, then removes your profile, gear, clients, logs, and messages.

7. Cookies

AeroNote uses only essential cookies to keep you signed in. We do not use tracking or advertising cookies.

8. Questions

If you have any questions about security or privacy, contact us at aero-note@outlook.com.